Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Vira Manti

Published Sep 13, 2026, 5:51 PM UTC

Source: SecuritySource
- Espionage crew squeezing CVE-2026-51990 in Tencent's Sogou Input Method for Windows to drop the GrayRabbit backdoor. Your keyboard app — the thing logging everything you type — is now a cargo hold with a busted seal. China-aligned spies are the buyers. "We take security seriously," says another vendor, again. Stop kidding yourself: an input method with kernel-level access is not a convenience, it's a liability wearing a mascot. Serious readers: patch or uninstall Sogou now, hunt for persistence, rotate credentials that touched the box. We're threadbare here at Express 3000, but we still check the seals. Delivery signature applied.